vendor:
MiniCMTS200a Broadband Gateway
by:
Zagros Bingol
7.5
CVSS
HIGH
Credential Disclosure
200
CWE
Product Name: MiniCMTS200a Broadband Gateway
Affected Version From: 2.0
Affected Version To: 2.0
Patch Exists: NO
Related CWE: N/A
CPE: a:atx:minicmts200a_broadband_gateway
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Debian 10 64bit
2020
ATX MiniCMTS200a Broadband Gateway 2.0 – Credential Disclosure
ATX/PicoDigital MiniCMTS200a Broadband Gateway v2.0 is vulnerable to credential disclosure. An attacker can send a POST request to the '/inc/user.ini' endpoint to retrieve usernames and hashes of the users.
Mitigation:
Ensure that the '/inc/user.ini' endpoint is not accessible from the internet and is only accessible from trusted networks.